Penetration Testing
UK

The following table provides summary statistics for permanent job vacancies with a requirement for Penetration Testing skills. Included is a benchmarking guide to the salaries offered in vacancies that have cited Penetration Testing over the 6 months to 8 May 2024 with a comparison to the same period in the previous 2 years.

6 months to
8 May 2024
Same period 2023 Same period 2022
Rank 447 476 556
Rank change year-on-year +29 +80 -137
Permanent jobs citing Penetration Testing 518 634 936
As % of all permanent jobs advertised in the UK 0.52% 0.62% 0.59%
As % of the Processes & Methodologies category 0.61% 0.65% 0.62%
Number of salaries quoted 408 423 652
10th Percentile £38,916 £43,477 £37,286
25th Percentile £47,500 £50,070 £50,375
Median annual salary (50th Percentile) £65,000 £67,500 £60,000
Median % change year-on-year -3.70% +12.50% -
75th Percentile £82,500 £90,000 £77,500
90th Percentile £95,000 £103,750 £90,000
UK excluding London median annual salary £55,000 £55,000 £60,000
% change year-on-year - -8.33% +9.09%

All Process and Methodology Skills
UK

Penetration Testing is in the Processes and Methodologies category. The following table is for comparison with the above and provides summary statistics for all permanent job vacancies with a requirement for process or methodology skills.

Permanent vacancies with a requirement for process or methodology skills 84,937 97,101 150,579
As % of all permanent jobs advertised in the UK 85.64% 95.61% 95.65%
Number of salaries quoted 59,853 57,006 82,680
10th Percentile £29,000 £34,000 £33,515
25th Percentile £40,000 £45,000 £43,750
Median annual salary (50th Percentile) £55,000 £61,180 £60,000
Median % change year-on-year -10.10% +1.97% +9.09%
75th Percentile £72,500 £81,250 £80,000
90th Percentile £92,500 £100,000 £96,750
UK excluding London median annual salary £50,000 £55,000 £52,500
% change year-on-year -9.09% +4.76% +9.38%

Penetration Testing
Job Vacancy Trend

Job postings citing Penetration Testing as a proportion of all IT jobs advertised.

Job vacancy trend for Penetration Testing in the UK

Penetration Testing
Salary Trend

3-month moving average salary quoted in jobs citing Penetration Testing.

Salary trend for Penetration Testing in the UK

Penetration Testing
Salary Histogram

Salary distribution for jobs citing Penetration Testing over the 6 months to 8 May 2024.

Salary histogram for Penetration Testing in the UK

Penetration Testing
Top 16 Job Locations

The table below looks at the demand and provides a guide to the median salaries quoted in IT jobs citing Penetration Testing within the UK over the 6 months to 8 May 2024. The 'Rank Change' column provides an indication of the change in demand within each location based on the same 6 month period last year.

Location Rank Change
on Same Period
Last Year
Matching
Permanent
IT Job Ads
Median Salary
Past 6 Months
Median Salary
% Change
on Same Period
Last Year
Live
Jobs
England +32 468 £65,000 -3.70% 117
UK excluding London -59 238 £55,000 - 67
London +76 228 £73,750 -10.30% 48
Work from Home -27 217 £60,000 -11.11% 63
South East +5 66 £43,750 -37.50% 15
South West -9 52 £55,000 +7.84% 20
Midlands -4 51 £55,000 -8.33% 7
North of England +19 50 £57,500 +9.52% 16
North West +13 38 £60,000 +12.15% 9
West Midlands -9 30 £55,000 -8.33% 2
East Midlands +2 21 £65,000 - 5
Yorkshire +55 12 £44,250 -15.71% 6
East of England -2 8 £41,250 -25.00%
Scotland -79 7 £60,000 +7.75% 3
Wales +6 3 £90,000 +50.00% 3
Channel Islands - 1 £100,000 -

Penetration Testing
Co-occurring Skills and Capabilities by Category

The follow tables expand on the table above by listing co-occurrences grouped by category. The same employment type, locality and period is covered with up to 20 co-occurrences shown in each of the following categories:

Application Platforms
1 5 (0.97%) Microsoft Exchange
2 4 (0.77%) SharePoint
3 2 (0.39%) Apache
4 1 (0.19%) Drupal
4 1 (0.19%) IIS
4 1 (0.19%) nginx
4 1 (0.19%) WebSphere
4 1 (0.19%) WordPress
Applications
1 2 (0.39%) Microsoft Office
Business Applications
1 1 (0.19%) Magento
1 1 (0.19%) Remedy ITSM
Cloud Services
1 110 (21.24%) Azure
2 81 (15.64%) AWS
3 50 (9.65%) Microsoft 365
4 27 (5.21%) GCP
5 19 (3.67%) Cloud Computing
6 11 (2.12%) Entra ID
6 11 (2.12%) Google Workspace
7 8 (1.54%) Amazon ECS
7 8 (1.54%) Cloudflare
7 8 (1.54%) PaaS
7 8 (1.54%) SaaS
8 7 (1.35%) Dynamics 365
8 7 (1.35%) IaaS
9 6 (1.16%) Azure Sentinel
10 5 (0.97%) Azure DevOps
11 4 (0.77%) Azure Service Bus
11 4 (0.77%) Mimecast
12 3 (0.58%) AWS Control Tower
12 3 (0.58%) Azure Synapse Analytics
12 3 (0.58%) Power Platform
Communications & Networking
1 127 (24.52%) Firewall
2 73 (14.09%) Network Security
3 39 (7.53%) Wireless
4 32 (6.18%) DNS
4 32 (6.18%) Intrusion Detection
5 18 (3.47%) Wi-Fi
6 17 (3.28%) TCP/IP
7 15 (2.90%) VPN
8 11 (2.12%) Broadband
8 11 (2.12%) NAS
9 10 (1.93%) Internet
9 10 (1.93%) Wireshark
10 9 (1.74%) SSL
11 6 (1.16%) BGP
11 6 (1.16%) LAN
12 5 (0.97%) HTTP
12 5 (0.97%) OSPF
12 5 (0.97%) SAN
12 5 (0.97%) SMTP
12 5 (0.97%) WAN
Database & Business Intelligence
1 10 (1.93%) SQL Server
2 6 (1.16%) MongoDB
2 6 (1.16%) NoSQL
3 4 (0.77%) InfluxDB
4 3 (0.58%) Data Lake
5 2 (0.39%) Azure SQL Database
6 1 (0.19%) Redis
Development Applications
1 39 (7.53%) Burp Suite
1 39 (7.53%) Metasploit
2 8 (1.54%) Git
2 8 (1.54%) Jenkins
3 5 (0.97%) JIRA
3 5 (0.97%) JMeter
3 5 (0.97%) Postman
4 4 (0.77%) SoapUI
5 3 (0.58%) Cucumber
5 3 (0.58%) SpecFlow
6 2 (0.39%) Bitbucket
6 2 (0.39%) Selenium
7 1 (0.19%) GitLab
7 1 (0.19%) Snyk
General
1 163 (31.47%) Social Skills
2 93 (17.95%) Analytical Skills
3 73 (14.09%) Finance
4 47 (9.07%) Legal
5 36 (6.95%) Law
6 30 (5.79%) Retail
7 29 (5.60%) Presentation Skills
8 26 (5.02%) Telecoms
9 25 (4.83%) Games
10 24 (4.63%) Banking
11 21 (4.05%) Aerospace
11 21 (4.05%) Inclusion and Diversity
12 19 (3.67%) Public Sector
13 18 (3.47%) Marketing
14 14 (2.70%) Influencing Skills
14 14 (2.70%) Military
15 8 (1.54%) Manufacturing
16 7 (1.35%) Automotive
16 7 (1.35%) Aviation
16 7 (1.35%) Pharmaceutical
Job Titles
1 132 (25.48%) Tester
2 131 (25.29%) Penetration Tester
3 73 (14.09%) Analyst
4 69 (13.32%) Lead
5 68 (13.13%) Senior
6 55 (10.62%) Security Analyst
7 40 (7.72%) Consultant
8 36 (6.95%) Security Engineer
9 34 (6.56%) Team Leader
10 32 (6.18%) Security Manager
11 27 (5.21%) Security Consultant
12 26 (5.02%) Cybersecurity Analyst
13 25 (4.83%) Architect
14 22 (4.25%) Senior Penetration Tester
14 22 (4.25%) Senior Tester
14 22 (4.25%) Test Team Leader
15 21 (4.05%) Security Tester
16 20 (3.86%) Security Architect
16 20 (3.86%) Security Penetration Tester
17 18 (3.47%) Cybersecurity Manager
Libraries, Frameworks & Software Standards
1 14 (2.70%) OAuth
2 12 (2.32%) OAuth2
3 8 (1.54%) Laravel
4 5 (0.97%) Web Services
5 4 (0.77%) EDI
5 4 (0.77%) OpenID
5 4 (0.77%) SOAP
5 4 (0.77%) XML
6 3 (0.58%) RESTful
6 3 (0.58%) WPF
7 2 (0.39%) SAML
8 1 (0.19%) ARM Templates
8 1 (0.19%) JSON
8 1 (0.19%) Kafka
8 1 (0.19%) Loki
8 1 (0.19%) React
8 1 (0.19%) SignalR
8 1 (0.19%) Spring
8 1 (0.19%) Spring Boot
8 1 (0.19%) YAML
Miscellaneous
1 58 (11.20%) Cyber Threat
2 42 (8.11%) Security Posture
3 41 (7.92%) Management Information System
4 37 (7.14%) Cyberattack
5 27 (5.21%) Mobile App
6 25 (4.83%) Onboarding
7 23 (4.44%) Self-Motivation
8 20 (3.86%) Operational Technology
9 16 (3.09%) Data Centre
10 14 (2.70%) Cyber Defence
10 14 (2.70%) Hybrid Cloud
11 13 (2.51%) Distributed Denial-of-Service
11 13 (2.51%) IoT
12 11 (2.12%) Video Conferencing
13 8 (1.54%) Cyber Security Posture
14 7 (1.35%) Analytical Mindset
14 7 (1.35%) Data Protection Act
15 6 (1.16%) Embedded Systems
16 5 (0.97%) Data Structures
16 5 (0.97%) SWIFT Messaging Network
Operating Systems
1 75 (14.48%) Windows
2 62 (11.97%) Linux
3 41 (7.92%) Kali Linux
4 25 (4.83%) Apple iOS
5 24 (4.63%) Android
5 24 (4.63%) Windows Server
6 15 (2.90%) Unix
7 12 (2.32%) Mac OS
8 3 (0.58%) Mac OS X
9 2 (0.39%) AIX
9 2 (0.39%) Red Hat Enterprise Linux
9 2 (0.39%) Windows 10
10 1 (0.19%) VMS
10 1 (0.19%) Windows Server 2012
10 1 (0.19%) Windows Server 2016
Processes & Methodologies
1 376 (72.59%) Cybersecurity
2 153 (29.54%) Information Security
3 117 (22.59%) Computer Science
4 113 (21.81%) Problem-Solving
5 102 (19.69%) Incident Response
6 95 (18.34%) Application Security
7 90 (17.37%) Vulnerability Scanning
8 87 (16.80%) Red Team
9 83 (16.02%) Security Testing
10 72 (13.90%) SIEM
11 64 (12.36%) Vulnerability Management
12 63 (12.16%) Mentoring
13 61 (11.78%) Vulnerability Assessment
14 57 (11.00%) Security Operations
15 54 (10.42%) OWASP
16 47 (9.07%) Patch Management
17 45 (8.69%) Risk Management
18 43 (8.30%) Data Protection
19 41 (7.92%) Malware Analysis
20 40 (7.72%) Reverse Engineering
Programming Languages
1 47 (9.07%) Python
2 31 (5.98%) Bash
3 14 (2.70%) Java
4 12 (2.32%) PowerShell
4 12 (2.32%) SQL
5 9 (1.74%) PHP
6 8 (1.54%) Rust
7 7 (1.35%) C#
7 7 (1.35%) Go
7 7 (1.35%) JavaScript
8 2 (0.39%) Ruby
9 1 (0.19%) Bicep
9 1 (0.19%) C++
9 1 (0.19%) TypeScript
Qualifications
1 122 (23.55%) Degree
2 105 (20.27%) CISSP
3 88 (16.99%) CREST Certified
4 69 (13.32%) OSCP
5 65 (12.55%) Computer Science Degree
6 58 (11.20%) CISM
7 52 (10.04%) Security Cleared
8 41 (7.92%) SC Cleared
9 39 (7.53%) CompTIA Security+
10 34 (6.56%) CEH
11 31 (5.98%) CHECK Team Member
12 29 (5.60%) GIAC
13 27 (5.21%) CISA
14 26 (5.02%) CompTIA CySA+
15 25 (4.83%) CHECK Team Leader
15 25 (4.83%) Cisco Certification
16 19 (3.67%) Network+ Certification
17 18 (3.47%) GPEN
18 16 (3.09%) Cyber Scheme
19 15 (2.90%) (ISC)2 CCSP
Quality Assurance & Compliance
1 101 (19.50%) ISO/IEC 27001
2 63 (12.16%) NIST
3 59 (11.39%) Cyber Essentials
4 30 (5.79%) GRC
5 28 (5.41%) Cyber Essentials PLUS
6 26 (5.02%) SOC 2
7 25 (4.83%) GDPR
8 24 (4.63%) PCI DSS
8 24 (4.63%) QA
9 10 (1.93%) NCSC
10 8 (1.54%) NIST 800
11 7 (1.35%) Actionable Recommendations
11 7 (1.35%) DO-254
12 6 (1.16%) ISO/IEC 27002 (supersedes ISO/IEC 17799)
13 5 (0.97%) COBIT
13 5 (0.97%) HIPAA
14 4 (0.77%) Accessibility
14 4 (0.77%) HMG Security Policy Framework
15 3 (0.58%) JSP 440
15 3 (0.58%) JTAG
System Software
1 47 (9.07%) Active Directory
2 27 (5.21%) VMware Infrastructure
3 9 (1.74%) Virtual Machines
4 7 (1.35%) Docker
5 2 (0.39%) Hyper-V
5 2 (0.39%) Virtual Servers
6 1 (0.19%) Firmware
6 1 (0.19%) VMware Server
Systems Management
1 21 (4.05%) Nessus
2 17 (3.28%) Kubernetes
3 13 (2.51%) WSUS
4 11 (2.12%) Ansible
4 11 (2.12%) Computer Emergency Response Teams
4 11 (2.12%) Single Sign-On
5 8 (1.54%) Microsoft Intune
5 8 (1.54%) Nmap
5 8 (1.54%) QRadar
6 7 (1.35%) SCCM
7 6 (1.16%) Terraform
8 5 (0.97%) CASB
8 5 (0.97%) Grafana
8 5 (0.97%) Progress Chef
8 5 (0.97%) Suricata
9 4 (0.77%) DatAdvantage
9 4 (0.77%) HP Fortify
10 3 (0.58%) FortiGate
11 2 (0.39%) CSIRT
12 1 (0.19%) Prometheus
Vendors
1 93 (17.95%) Microsoft
2 27 (5.21%) VMware
3 22 (4.25%) Cisco
3 22 (4.25%) Qualys
4 20 (3.86%) Google
5 15 (2.90%) Splunk
6 11 (2.12%) Apple
7 8 (1.54%) Palo Alto
8 6 (1.16%) HubSpot
8 6 (1.16%) Oracle
8 6 (1.16%) Rapid7
9 5 (0.97%) IBM
9 5 (0.97%) Juniper
9 5 (0.97%) Kenna
9 5 (0.97%) Red Hat
9 5 (0.97%) Veeam
10 4 (0.77%) Alibaba
10 4 (0.77%) Darktrace
10 4 (0.77%) HP
10 4 (0.77%) ServiceNow